RHSA-2011:0266: Low: fence security, bug fix, and enhancement update
The fence package allows failed or unreachable nodes to be forcibly<br>restarted and removed from a cluster.<br>Insecure temporary file use flaws were found in fenceegenera, fenceapc,<br>and fenceapcsnmp. A local attacker could use these flaws to overwrite an<br>arbitrary file writable by the victim running those utilities via a<br>symbolic link attack. (CVE-2008-4192, CVE-2008-4579)<br>This update also fixes the following bugs:<br><li> fenceapcsnmp now waits for five seconds after fencing to properly get</li> status. (BZ#494587)<br><li> The fencedrac5 help output now shows the proper commands. (BZ#498870)</li> <li> fencescsitest.pl now verifies that sgpersist is in the path before</li> running. (BZ#500172)<br><li> fencedrac5 is now more consistent with other agents and uses modulename</li> instead of modulename. (BZ#500546)<br><li> fenceapc and fencewti no longer fail with a pexpect exception.</li> (BZ#501890, BZ#504589)<br><li> fencewti no longer issues a traceback when an option is missing.</li> (BZ#508258)<br><li> fencesanbox2 is now able to properly obtain the status after fencing.</li> (BZ#510279)<br><li> Fencing no longer fails if fencewti is used without telnet. (BZ#510335)</li> <li> fencescsi getscsidevices no longer hangs with various devices.</li> (BZ#545193)<br><li> fenceilo no longer fails to reboot with ilo2 firmware 1.70. (BZ#545682)</li> <li> Fixed an issue with fenceilo not rebooting in some implementations.</li> (BZ#576036)<br><li> fenceilo no longer throws exceptions if the user does not have power</li> privileges. (BZ#576178)<br>As well, this update adds the following enhancements:<br><li> Support has been added for SSH-enabled RSA II fence devices. (BZ#476161)</li> <li> The APC fence agent will now work with a non-root account. (BZ#491643)</li> All fence users are advised to upgrade to this updated package, which<br>corrects these issues and adds these enhancements.<br>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2011:0266?
The severity of RHSA-2011:0266 is classified as moderate.
How do I fix RHSA-2011:0266?
To fix RHSA-2011:0266, update the affected fence package to the latest version provided by Red Hat.
What types of flaws are addressed in RHSA-2011:0266?
RHSA-2011:0266 addresses insecure temporary file use flaws in several fencing agents.
Who is affected by RHSA-2011:0266?
Local attackers on systems utilizing the affected fence package are at risk from RHSA-2011:0266.
What impact does RHSA-2011:0266 have on system security?
The impact of RHSA-2011:0266 is that it allows local attackers to potentially overwrite arbitrary files.